Magento 2 CSP Reports Extension

Hyva icon

Magento 2 CSP Extension tap to zoom

version 1.0.2
Price: Free
  • CE: 2.3.5 - 2.4.9
    EE: 2.3.5 - 2.4.9
  • 100%
    Open Code
  • 60 Days
    Refund Policy
  • Marketplace
    Approved

Magento 2 CSP Reports is a free extension that enhances the security workflow for Magento admins by providing detailed reports and notifications of blocked resources. This enables admins to control the Magento 2 content security policy (CSP), timely address any issues that arise, and ensure a secure browsing experience for customers.



  • Leverage from detailed CSP reports and admin notifications

  • Change CSP modes directly from the admin panel

  • Keep the CSP report clean and informative by removing resolved issues


  • CE: 2.3.5 - 2.4.9
    EE: 2.3.5 - 2.4.9
  • 100%
    Open Code
  • 60 Days
    Refund Policy
  • Marketplace
    Approved
Product Details
Version: 1.0.2 (Oct 21, 2025)
Documentation: User Guide
Live Demo: View
Code Visibility: 100% Open Code
Supported CE - EE: CE 2.3.5 - 2.4.9
EE 2.3.5 - 2.4.9
License: Single Magento Installation
Support Plan: 12 months
Updates: Free Updates
Refund Policy: 60 Days (View)

Key Features of Magento 2 CSP Reports Extension

Take Security Measures to Avoid Data Injection Attacks

Take Security Measures to Avoid Data Injection Attacks

Take Security Measures to Avoid Data Injection Attacks

Enhance your Magento store security by monitoring and quickly addressing any potential CSP vulnerabilities.
Provide customers with a secure online shopping experience by preventing card skimmers, session hijacking, clickjacking, etc.

Gain Comprehensive Magento 2 CSP Reports

Gain Comprehensive Magento 2 CSP Reports
Benefit from a detailed reports grid that shows admins a comprehensive view of resources that were restricted from loading on a specific page.
The Magento 2 CSP Reports grid informs you of what resources were restricted from loading, when, on what page, their host, and directive.
Keep the report clean and informative - specify the number of days after which the report will be deleted from the grid if not reported again.

Stay Alert with Admin Notification for New CSP Violations

Stay Alert with Admin Notification for New CSP Violations

Stay Alert with Admin Notification for New CSP Violations

The Magento 2 CSP extension provides a notification system that keeps administrators informed about new reports.
By receiving notifications, admins can timely act on policy violations and take appropriate actions to minimize vulnerability risks.

Effortlessly Manage CSP Modes from the Admin Panel

Effortlessly Manage CSP Modes from the Admin Panel
Configure CSP modes separately for admin and storefront areas to have granular control over the allowed content sources and customize settings based on your specific needs.
In the “Report Only” CSP mode, Magento reports policy violations but does not take any actions, which is a safe transition of your website to a “Restrict” mode.
In the “Restrict” CSP mode, Magento both reports policy violations and acts on them by blocking these resources. This mode is highly recommended for the admin area to keep sensitive customer data secure.

Overview of Magento 2 CSP Reports Extension

Starting from 2.3.5 version, Magento supports Content Security Policies (CSP) module - powerful functionality that controls resources the browser is allowed to load for a specific page. This ensures website protection against Cross Site Scripting (XSS) attacks, including card skimmers, session hijacking, and more. Magento also provides the ability to configure the functionality at the programming level, which requires coding skills and lacks a violation monitoring tool for admins.

Our FREE Magento 2 CSP Module streamlines security management for both developers and admins. Store admins can configure CSP modes directly from the admin panel and effectively monitor policy violations with a user-friendly CSP reports grid. This enables timely issue identification and fixing to ensure a secure online shopping experience for customers. Additionally, the extension reduces the time for developers to whitelist safe resources and delete others.

All Features:

  • NEW! Magento 2 CSP Reports Extension is compatible with Hyvä Themes
  • Ability to change the Magento 2 Content Security Policy mode to “Restrict” or “Report Only” directly from the admin panel, separately for the storefront and admin areas
  • Displaying Magento 2 Content Security Policy violation report in a convenient grid view
  • The Magento 2 CSP report grid includes the following information: Host and Violated Directive, Resource URL and Page URL where the violation occurred, Action (reporting or blocking the resource), Report Count, and Last Report Date
  • Ability to clean up the report from errors that haven't been reported again in a specified time period
  • Admin notification about each new Content Security Policy violation
  • 100% open code Magento 2 extension

Reviews of Magento 2 CSP Reports Extension

Stylus icon Write a Review

Every customer will automatically receive
$10 in reward points for each approved review.

  • Works well
    United States Marcus Thorne posted on February 12, 2026. Review for Magento 2.x
    Free and useful, no complaints. Clean reports in the admin grid, notifications when something new pops up. Hard to ask for more out of a free tool.
  • Excellent tool considering the "Price"
    Germany Rodrigo Rodrigues posted on November 17, 2025. Review for Magento 2.x
    Managing CSP policies are very easy! The reports are clear, and the notifications helps us to keep on top of security issues without wasting time digging through logs.
    A must have tool for Magento 2
  • A Must-Have for Magento Security
    United States Amir posted on February 03, 2025. Review for Magento 2.x
    This extension makes managing CSP policies super easy! The reports are clear, and the admin notifications help me stay on top of security issues without digging through logs. A great free tool for any Magento store owner!
  • Customer photo
    It's free and awesome!
    I'm using it on: cepmania.com, cepmania.net
    Turkey ERCAN KÖKSEL posted on September 11, 2023. Review for Magento 2.x
    It's really great that such a extension is free.
    It gives you very valuable information in the background.

    Plumrocket is always my favourite.

    Thank you so much again!

FAQ of Magento 2 CSP Reports Extension

It adds a reporting and notification layer on top of Magento's built-in Content Security Policy (CSP) module. It shows admins which resources were blocked or flagged on the storefront and admin panel, when, and why, so security issues can be caught and fixed without digging through server logs.

Yes, the extension is compatible with Hyvä Themes.

Content Security Policy helps block Cross-Site Scripting (XSS) attacks, including card skimmers, session hijacking, and clickjacking, by controlling which resources a browser is allowed to load on a given page.

Install it like any Plumrocket Magento 2 extension via Composer or manual file upload, then run setup upgrade and static content deploy. Full steps are in the Installation guide in the documentation.

Report Only logs policy violations without blocking anything, which is useful for testing. Restrict mode both reports and actively blocks violating resources.

Yes. Storefront Mode and Admin Mode are configured separately, so you can run Report Only on the storefront while keeping Restrict mode active in the admin area for stronger protection of customer data.

Use the "Erase Outdated Reports After (days)" setting in Configuration. Any violation that hasn't reoccurred within that number of days is automatically cleared from the grid.

Go to Plumrocket > CSP Reports > Reports in the admin menu. The grid shows the host, violated directive, resource and page URL, action taken, report count, and last report date.

Yes, the CSP Reports extension for Magento 2 sends admin notifications for each new Content Security Policy violation so issues can be addressed promptly rather than discovered later.

Fully disabling the Csp module removes Magento's built-in security headers store-wide and isn't recommended. A safer option is switching Storefront Mode to "Report Only" in Plumrocket > CSP Reports > Configuration. This stops CSP from blocking any resources while still logging violations, so you get the effect of disabling enforcement without losing visibility.

Whitelisting is configured in code, either through a csp_whitelist.xml file or, for inline scripts, by using a nonce. Plumrocket CSP Reports extension for Magento 2 doesn't add whitelisting itself, but its reports grid shows the exact host, directive, and resource URL behind each violation, so developers know precisely what to add without digging through browser console logs.

Change Log of Magento 2 CSP Reports Extension

Legend:  - new feature - bug fix

Version 1.0.2 Oct 21, 2025

  • Added compatibility with PHP 8.4

Version 1.0.1 Jul 04, 2023

  • Fixed installation via composer on Magento v2.4.6

Version 1.0.0 Jun 29, 2023

  • Created CSP Reports extension for Magento 2